Sceawere
Vulnerability Detail
CVE-2026-102459UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in EasyFlow .NET
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- DigiWin
- Product
- EasyFlow .NET
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-09-30T09:17:13.953Z",
"pubdate": "2026-09-30T09:17:13.953Z",
"executiveSummary": "EasyFlow .NET, developed by Digiwin, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability.\nThis flaw allows unauthenticated remote attackers to execute arbitrary JavaScript code within the context of a victim's web browser session.\nThe vulnerability stems from improper input validation of user-supplied data reflected in the server's HTTP responses.\nThe primary attack vector involves social engineering, such as phishing, where an attacker convinces a user to click a specially crafted malicious link.\nSuccessful exploitation compromises the integrity of the user's session and the confidentiality of data processed within the application.\nThe risk is high, as the vulnerability does not require authentication, allowing any remote attacker to facilitate the execution of malicious scripts against legitimate users.\nThe impact includes session hijacking, unauthorized actions performed on behalf of the user, and the potential exfiltration of sensitive information displayed in the browser.",
"technicalDetails": "The Reflected Cross-Site Scripting (XSS) vulnerability in EasyFlow .NET occurs due to the application's failure to properly sanitize or encode user-controllable input before rendering it back to the client browser in an HTTP response.\nIn a typical Reflected XSS scenario, the application includes data from an HTTP request (such as URL parameters or query strings) directly into the generated HTML markup without appropriate contextual output encoding.\nAn attacker exploits this by crafting a malicious URL containing a payload—typically a script block or an event handler—designed to execute when the server reflects the payload back to the browser.\nThe attack flow proceeds as follows: First, the attacker identifies a vulnerable input field or URL parameter within the EasyFlow .NET application that is reflected in the resulting response. Second, the attacker embeds a malicious JavaScript payload into this parameter and uses social engineering techniques, such as phishing, to trick an authenticated user into clicking the crafted link. Third, when the victim visits the link, the server receives the malicious request and returns an HTTP response containing the injected script. Fourth, the victim's browser, trusting the origin of the page, parses and executes the injected JavaScript code.\nBecause the payload executes within the security context of the EasyFlow .NET session, the attacker can bypass Same-Origin Policy (SOP) restrictions to access sensitive session identifiers, such as cookies, or perform unauthorized actions. This can lead to the full compromise of the user's session. The execution is entirely client-side and requires no specific privileges on the server side, as the vulnerability is triggered by the victim's interaction. The reliance on external triggers like phishing makes this a persistent threat against users of the platform, as there is no requirement for the attacker to have pre-existing access to the internal network or the application's administrative interface. Post-exploitation impact may include the redirection of users to malicious sites, the modification of page content to capture credentials, or the silent exfiltration of sensitive data currently being viewed by the user."
}